CVE-2016-1498
Publication date 8 January 2016
Last updated 17 July 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| owncloud | ||
| 14.04 LTS trusty | Not in release | |
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.1 · Medium
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N